Removal of Activation Overlay/Watermark in unactivated RTM. Need Help!

Discussion in 'Windows 8' started by dummekuehe, Aug 7, 2012.

  1. dummekuehe

    dummekuehe MDL Senior Member

    Jan 11, 2009
    495
    112
    10
  2. Chris123NT

    Chris123NT MDL Expert

    Oct 23, 2010
    1,070
    793
    60
    Does this program just restart explorer or does it actually remove it without killing the shell 48 times a day lol.
     
  3. pankaka

    pankaka MDL Novice

    Aug 9, 2012
    1
    0
    0
    WatermarksKiller dont work here on my W8 Pro 32 bit. Its dim out a little bit, that all.
     
  4. Mrx47

    Mrx47 MDL Addicted

    Apr 6, 2011
    571
    90
    30
    I've deleted this key-picture from the watermark from twinui.dll. Now, only the text appears. I don't know how to disable this text.
     
  5. WinFührer

    WinFührer MDL Novice

    Jun 17, 2011
    42
    13
    0
    This text is encrypted on the registry, probably
     
  6. LiveFreeDead

    LiveFreeDead MDL Member

    Aug 3, 2012
    122
    77
    10
  7. vali20

    vali20 MDL Member

    Aug 8, 2012
    123
    60
    10
    The "Activate Windows" text is located in String Table at folder 1522 in shell32.dll.mui. The image can be removed from twinui.dll. I don't know where the text "Go to PC settings to activate Windows" is located.
     
  8. LiveFreeDead

    LiveFreeDead MDL Member

    Aug 3, 2012
    122
    77
    10
    #9 LiveFreeDead, Aug 9, 2012
    Last edited: Aug 9, 2012
    my Enterprise x64 doesn't have that string resource folder number, only has a couple of 1000 rage items actually, you sure that's the right information? or U using Pro and it's changed?

    -EDIT-

    Nevermind, I opened the mui in Resource Hacker instead of that other one I killed the bmp's in twinui.dll and it's got that folder.

    -Edit-

    Found it at 24341 in the Res Edit tool. as shown in Resource Hacker
     
  9. vali20

    vali20 MDL Member

    Aug 8, 2012
    123
    60
    10
    #10 vali20, Aug 9, 2012
    Last edited: Aug 9, 2012
    I am using Windows 8 RTM Enterprise x64 and I had installed the Romanian Multilingual User Interface Pack (I think this is relevant). I'll post a screenshot soon, keep refreshing the page. Image link: imageshack.us/photo/my-images/825/shot1r.png/
     
  10. LiveFreeDead

    LiveFreeDead MDL Member

    Aug 3, 2012
    122
    77
    10
    #11 LiveFreeDead, Aug 9, 2012
    Last edited: Aug 9, 2012
    I used Hexprobe to search for "Activate Windows" there are heaps of them

    Then I searched for "Go to se" and it found nothing...

    I tried "47 00 6F 00 20 00 74 00 6F 00 20 00 73 00 65" which is the same in hex/unicode and it still found nothing

    I tried the same in regedit and came up empty... Not sure where the text lives yet, well I'll just try the twinui.dll Key bitmap fix, better than nothing for now :)

    -EDIT-

    It occured to me that they might use the universal "Settings" string and separate the "Go to"... will look tomorrow I guess.
     
  11. woot332

    woot332 MDL Senior Member

    Feb 18, 2011
    390
    815
    10
    Patch DrawTextExW inside twinui.dll and watermark string is gone;)
     
  12. vali20

    vali20 MDL Member

    Aug 8, 2012
    123
    60
    10
    Hello, woot332, can you be more explicit? What to patch and how? Do I need to use Resource Hacker or what tool? Please answer fast, I'm gonna do it 'till night. I hate watching movies with this watermark. Thanks for your info anyway, Vali.
     
  13. LiveFreeDead

    LiveFreeDead MDL Member

    Aug 3, 2012
    122
    77
    10
    #14 LiveFreeDead, Aug 9, 2012
    Last edited: Aug 9, 2012
    woot332, if you do that nothing can use it, including any MS tools that might try to use it for Stuff, like Subtitles, Status and Loading Screens and things like that...

    I am not a hacker, the most basic job I did is change je to jmp and nop out text. I wouldn't know how to disable a API in a dll either ;)

    Guess I'll have to learn tho... or wait till someone with more experience comes along and has a kind heart.
     
  14. aurise

    aurise MDL Novice

    Jun 3, 2007
    29
    1
    0
    there is "RoGetActivationFactory" string at 4f751c address in twinui.dll in system32

    if that could be patched somehow to point to something empty
     
  15. LiveFreeDead

    LiveFreeDead MDL Member

    Aug 3, 2012
    122
    77
    10
    Yeah that seems like a better candidate, if we disassembler and add a exit command (very rusty on my asm, don't know what to use), then it may skip the call to the DrawTextExW from the RoGetActivationFactory, or we can trace the call to it... might have to dust off ollydb and IDM Disassembler to figure this out... someone smarter really should be doing this tho, would take me days to figure it out and I'd probably not use that skill again for another 4 years :D
     
  16. Helmutcheese

    Helmutcheese MDL Member

    Jul 29, 2009
    182
    27
    10
    "My WCP Watermark Editor" worked on all builds of Win 8 64bit for me from Beta/RC to RTM.
     
  17. UnknownRE

    UnknownRE MDL Junior Member

    Aug 8, 2012
    52
    4
    0
    #19 UnknownRE, Aug 9, 2012
    Last edited: Aug 9, 2012
    I will try to update the tool because it does not work on any other computer sorry for the mis-post
     
  18. bjf2000

    bjf2000 MDL Expert

    Apr 11, 2008
    1,086
    197
    60
    I wanted to start off small by trying that. Found it, killed it, but the key is still there. How can that be? Enterprise.